Latest Dynatrace Preview
The Dynatrace integration with VirusTotal brings threat intelligence context into alerts and detection investigations to help organizations combat online abuse, such as cyber-attacks, spamming, and other malicious activities.
With observable enrichment with reputation generated from the threat information provided by VirusTotal, you can perform more efficient security investigations and automate alert triaging, reducing the noise with threat-aware prioritization.
Dynatrace integration with VirusTotal is an app that you can install from Dynatrace Hub.
The app delivers a workflow action for observable enrichment in Workflows.
Once the app is installed and configured
Various consumer apps can perform an on-demand enrichment of observables, such as IP addresses.
During the enrichment, Dynatrace reaches out to VirusTotal to perform the observable enrichment.
The threat intelligence context is displayed within the consumer apps or in Workflows.
Register with VirusTotal and create an API v3 key.
In Dynatrace, open Dynatrace Hub.
Look for VirusTotal and select Install.
Select Set up , then select Configure new connection.
Follow the on-screen instructions to set up the connection using the API key obtained in Prerequisites.
Allowed outbound connections are extended automatically with www.virustotal.com
.
Test the connection to ensure the correct configuration and save it.
Once you set up the VirusTotal integration, you can enrich observables, such as IP addresses, with threat intelligence context.
Key use cases include:
Threat-informed security investigations Coming soon
Automated threat-alert triaging Coming soon
Supported observable types: IP addresses (more coming soon).
For every new observable enrichment, we perform a single API call.